BENGALURU, India, September 15, 2026 — Trellix, a global leader in cyber resilience for the AI era, highlighted findings from its latest Trellix Second Sight Threat Hunting Report with implications for Indian organizations. Examining five critical campaigns observed between January and June 2026, the report details diplomatic espionage in Asia, credential theft targeting Southeast Asia, and a global open-source supply chain compromise. These investigations illustrate how attackers exploit trusted accounts and software, offering lessons for Indian security teams assessing exposure in their own environments.
Trellix Second Sight Threat Hunting Report highlights:
- A repeat diplomatic target in Asia: A June 2026 spear-phishing campaign against a European embassy located in Asia, attributed to Bitter APT, used a compromised diplomatic mailbox from an African country and a FIFA World Cup themed lure to deploy the BDarkRAT remote access trojan. Trellix Second Sight hunters traced the campaign's command-and-control domain back to an October 2025 attack on the same embassy, confirming a sustained, calculated espionage effort rather than an isolated intrusion.
- A stealthy credential stealer targeting Southeast Asia: Active through the first half of 2026, the JSCeal campaign used an encoded PowerShell script to deploy a legitimate Node.js runtime alongside an encrypted, in-memory payload built to harvest browser-stored passwords, session cookies, and cryptocurrency wallet data from Southeast Asia-based organizations. Trellix SecondSight hunters traced the intrusion by following the PowerShell-to-Node.js execution chain back to its source and reverse engineering the payload's decryption logic.
- A widely used open-source package compromised at the source: The March 2026 compromise of Axios, a JavaScript library downloaded roughly 100 million times weekly, followed the takeover of a maintainer's npm account and the publication of two malicious package versions installing a cross-platform remote access trojan. Working from public threat intelligence, Trellix Second Sight hunters identified the indicators in Trellix telemetry, reconstructed affected environments, and notified impacted customers, including organizations whose development environments may have been exposed through the compromised dependency.
“For organizations in India, these findings are a reminder that exposure can come through the software, accounts and suppliers they rely on every day,” said Ganesh Iyer, Managing Director, Trellix, India & SAARC. “A familiar application or a trusted sender does not guarantee that the activity is safe. Security teams need to connect what they know about emerging threats with what is happening in their own environments. Proactive threat hunting helps them investigate those connections early, so they can act before an intrusion becomes a wider business disruption.”
The report also examines an APT28 espionage campaign targeting European organizations and a nation-state iOS exploit chain. Across the five investigations, it shows how threat intelligence, AI-powered automation and human expertise can help security teams connect seemingly isolated activity and turn findings into defensive action.